ASA-201901-2 generated external raw

[ASA-201901-2] polkit: privilege escalation
Arch Linux Security Advisory ASA-201901-2 ========================================= Severity: High Date : 2019-01-08 CVE-ID : CVE-2018-19788 Package : polkit Type : privilege escalation Remote : No Link : https://security.archlinux.org/AVG-828 Summary ======= The package polkit before version 0.115+24+g5230646-1 is vulnerable to privilege escalation. Resolution ========== Upgrade to 0.115+24+g5230646-1. # pacman -Syu "polkit>=0.115+24+g5230646-1" The problem has been fixed upstream but no release is available yet. Workaround ========== None. Description =========== A security issue has been found in polkit <= 0.115, where an unprivileged user with a UID > INT_MAX can successfully execute any systemctl command. Impact ====== A local, unprivileged user whose UID is larger than INT_MAX can escalate privileges. References ========== https://seclists.org/oss-sec/2018/q4/198 https://gitlab.freedesktop.org/polkit/polkit/issues/74 https://gitlab.freedesktop.org/polkit/polkit/commit/2cb40c4d5feeaa09325522bd7d97910f1b59e379 https://security.archlinux.org/CVE-2018-19788